iv — Initialization Vector

Location: header · Format: string

Base64url-encoded initialization vector used by AES-GCM key-wrapping algorithms (A*GCMKW) to wrap the content-encryption key. Reusing an IV with the same key under GCM is catastrophic — it breaks both confidentiality and authenticity of everything encrypted under that key/IV pair.

Defined in RFC 7518 §4.7.1.1.

Decode a JWT and inspect its iv claim in the TokenPrism debugger — free, entirely in your browser.